CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 10: CS0-001: CompTIA CySA+ Certification Exam

A cybersecurity analyst has several SIEM event logs to review for possible APT activity. The analyst was given several items that include lists of indicators for bothIP addresses and domains. Which of the following actions is the BEST approach for the analyst to perform?

Nội dung câu hỏi

A cybersecurity analyst has several SIEM event logs to review for possible APT activity. The analyst was given several items that include lists of indicators for bothIP addresses and domains. Which of the following actions is the BEST approach for the analyst to perform?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Use the IP addresses to search through the event logs.
  2. B. Analyze the trends of the events while manually reviewing to see if any of the indicators match. — đáp án hiện tại
  3. C. Create an advanced query that includes all of the indicators, and review any of the matches.
  4. D. Scan for vulnerabilities with exploits known to have been used by an APT.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề